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This article introduces Smart Packets and describes the smart Packets architecture, the 
packet formats, the language and its design goals, and security considerations. Smart 
Packets is an Active Networks project focusing on applying active networks technology to 
network management and monitoring. Messages in active networks are programs that are 
executed at nodes on the path to one or more target hosts. Smart Packets programs are 
written in a tightly encoded, safe language specifically des ... 
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Extensive caching is a key feature of the Echo distributed file system. Echo client 
machines maintain coherent caches of file and directory data and properties, with write- 
behind (delayed write-back) of all cached information. Echo specifies ordering constraints 
on this write-behind, enabling applications to store and maintain consistent data 
structures in the file system even when crashes or network faults prevent some writes 
from being completed. In this paper we describe ... 
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An organized record of actual flaws can be useful to computer system designers, 
programmers, analysts, administrators, and users. This survey provides a taxonomy for 
computer program security flaws, with an Appendix that documents 50 actual security 
flaws. These flaws have all been described previously in the open literature, but in widely 
separated places. For those new to the field of computer security, they provide a good 
introduction to the characteristics of security flaws and how they ... 
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The Secure Virtual Enclaves (SVE) collaboration infrastructure allows multiple 
organizations to share their distributed application objects, while respecting organizational 
autonomy over local resources. The infrastructure is transparent to applications, which 
may be accessed via a web server, or may be based on Java or Microsoft's DCOM. The 
SVE infrastructure is implemented in middleware, with no modifications to COTS operating 
systems or network protocols. The system enables dynamic updates to ... 
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This paper presents the access control mechanisms in Windows 2000 that enable fine- 
grained protection and centralized management. These mechanisms were added during 
the transition from Windows NT 4.0 to support the Active Directory, a new feature in 
Windows 2000. We first extended entries in access control lists to allow rights to apply to 
just a portion of an object. The second extension allows centralized management of object 
hierarchies by specifying more precisely how access control lis ... 
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When personal machines are incorporated into distributed systems a new mixture of 
threats is exposed. The security effort in the MobyDick project is aimed at understanding 
how privacy can be protected in this new environment. Our claim is that a two-step 
process for authentication and authorisation is required, but also sufficient. The research 
vehicle is a distributed file repository. 
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We present a security architecture that enables system and application a ccess control 
requirements to be enforced on applications composed from downloaded executable 
content. Downloaded executable content consists of messages downloaded from remote 
hosts that contain executables that run, upon receipt, on the downloading principal's 
machine. Unless restricted, this content can perform malicious actions, including 
accessing its downloading principal's private data and sending messages on th ... 

Keywords: access control models, authentication, autorization machanisms, collaborative 
systems, role-based access control 
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The Security Process Algebra (SPA) is a CCS-like specification languag e where actions 
belong to two different levels of confidentiality. It has been used to define several 
noninterference-like security properties whose verification has been automated by the tool 
CoSeC. In recent years, a method for analyzing security protocols using SPA and CoSeC 
has been developed. Even if it has been useful in analyzing small security protocols, this 
method has shown to be error-prone, as it requires the ... 
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No secure network file system has ever grown to span the Internet. Existing systems all 
lack adequate key management for security at a global scale. Given the diversity of the 
Internet, any particular mechanism a file system employs to manage keys will fail to 
support many types of use. We propose separating key management from file system 
security, letting the world share a single global file system no matter how individuals 
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